正解:C
Comprehensive and Detailed Step-by-Step Explanation:
In forensic investigations,maintaining a proper chain of custodyiscriticalto ensuring that evidence is admissible in court and has not been altered.
* Option A (Incorrect):Activatingsecurity features(e.g., encryption or tokenization) is apreventive measurebut does not aid in investigating the attack.
* Option B (Incorrect):Blocking payment platforms may be necessary fordamage control, but it does not ensure a properinvestigation.
* Option C (Correct):Thechain of custodyensures thatevidence remains intact, can betraced, and is legally validfor prosecution. This is the most critical aspect of forensic investigations.
* Option D (Incorrect):Interviewing staff may provide insights, but without properevidence handling, the investigation's integrity is at risk.
Reference:ISACA CISA Review Manual -Domain 5: Protection of Information Assets- Coversforensic investigations, evidence handling, and legal compliance.